15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

2026-07-08T07:24:07Z7fb9fe048c7fe67c9616993d9974af2d299b3758d5e1c20e69d5d329614429cd
CISA-KEVactively-exploitedagentic-workflowsair-gapandroid-maasauthentication-bypasscloud-securitycontainer-escapeexfiltrationfirmware-backdoorgithubkvmlinux-kernelmalwarephishingprivilege-escalationransomwareremote-code-executionroot-escaperoutersupply-chain

What happened

A collection of active and high-impact cyber threats and disclosures: Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that enables any logged-in user to obtain root on unpatched mainstream distributions. Multiple other critical flaws and active exploitations were reported — including an Adobe ColdFusion RCE added to CISA KEV (CVE-2026-48282), a KVM guest-to-host escape dubbed Januscape (CVE-2026-53359), and active probes targeting a critical Gitea Docker issue (CVE-2026-20896). Vendor and device advisories include a Tenda firmware hidden admin‑byp

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
7fb9fe048c7fe67c9616993d9974af2d299b3758d5e1c20e69d5d329614429cd
Enrichment time
2026-07-08T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros · Baitaphish